Cursor IDE Auto-Executes Malicious Code in Poisoned Repos
Researchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository attacks.
ACTIVE THREATS: How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know • AVEVA Pipeline Integrity Monitor ACTIVE THREATS: How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know • AVEVA Pipeline Integrity Monitor
The full HackWire archive — 3,891 stories, newest first.
Researchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository attacks.
Attackers exploit OAuth client ID spoofing to validate stolen credentials against Microsoft Entra ID without detection. Two groups have compromised millions of accounts since December 2025.
Two RabbitMQ vulnerabilities enable broker compromise and data theft. CVE-2026-57219 exposes OAuth secrets via unauthenticated endpoint access, while CVE-2026-57221 bypasses authorization and breaches multi-tenant isolation.
A KU Leuven study found crypto wallet extensions leak identifying data, allowing address linking and cross-site tracking. Users' supposedly anonymous addresses are traceable to their real identity.
Eleven Microsoft-signed apps contain UEFI Secure Boot bypass vulnerabilities, enabling attackers to deploy persistent firmware malware on enterprise and cloud systems. Legacy compatibility prioritizes functionality over security, creating a recurring pattern that patching alone cannot solve.
Two phishing kits, Jalisco and OmegaLord, bypass Microsoft 365 MFA using reverse proxy and token interception, allowing attackers to hijack authenticated sessions without detection.
Starting September 2026, Microsoft makes passkeys the default for Entra ID, preventing the 99.9% of account compromises tied to password vulnerabilities and phishing attacks.
TTP chaining validates vulnerabilities by testing underlying attack techniques rather than executing exploits—letting security teams assess exploitability in production environments without triggering alarms.
SAP patched three critical flaws: memory corruption in NetWeaver, HTTP smuggling in Approuter, and hardcoded credentials in Commerce Cloud. All enable unauthenticated attackers to access or crash enterprise systems.
Grok Build secretly uploaded entire Git repositories to xAI storage, transmitting 27,800x more data than needed. The uploader included unread files and unredacted secrets with no user opt-out.
OFAC sanctioned First VPN Service and a malware developer enabling ransomware attacks, blocking US assets and transactions. The enforcement targets criminal infrastructure providers rather than attackers themselves—a strategic shift in disrupting ransomware ecosystems.
Microsoft redesigns Windows Search to prioritize local files over ads. Now available to Windows Insiders, this update addresses years of complaints about cluttered, ad-heavy search results.
SAP released patches for three critical flaws: NetWeaver memory corruption, unauthenticated AppRouter smuggling, and Commerce Cloud defaults. Enterprises must patch urgently.
Jscrambler NPM packages were poisoned with credential-stealing malware affecting 1,479 developers via preinstall hooks. The compromise extended to downstream dependencies, revealing persistent open-source supply chain vulnerabilities.
ShinyHunters used OAuth phishing to bypass Salesforce security for a year, targeting CRM data across sectors. Attackers authorized malicious apps rather than exploiting platform vulnerabilities.
148 npm packages disguised as student proxies converted browsers into a DDoS botnet attacking a nursing school. The supply chain attack reveals new vulnerabilities in open-source security.
The US sanctioned First VPN Service for enabling ransomware attacks against critical infrastructure—the first VPN OFAC has penalized—marking escalated enforcement against cyber attack infrastructure.
Grok Build uploaded entire Git repositories—including credentials and proprietary code—to xAI's cloud storage without consent. Testing revealed a 27,800x disparity between data the model needed and what was actually transmitted, suggesting wholesale repository collection rather than targeted file ac
A ransomware negotiation firm was exposed sharing victims' insurance details and negotiation strategies with criminal gangs to maximize payouts. The breach reveals critical vulnerabilities in third-party incident response vendor selection and trust.
The Pentagon suspended CMMC Phase 2 and established a task force to overhaul the defense contractor cybersecurity program. The pause stems from concerns over implementation complexity, costs, and readiness across the defense industrial base.
ShinyHunters stole Salesforce data by compromising OAuth-approved apps. Attackers inherited pre-approved permissions, bypassing Salesforce vulnerabilities to steal customer data over 12 months.
Russian FSB hackers exploit weak router security in critical infrastructure sectors globally. US and allied nations responded with coordinated warnings and sanctions on 24 Russian entities—a rare unified cyber deterrence effort.
**Nihon Kotsu's taxi dispatch systems went offline after a cyberattack, affecting services across Tokyo. Booking and reservation systems remain down 48+ hours later, disrupting urban transportation.**
Russian FSB actors exploit poorly configured routers with default SNMP credentials to infiltrate critical infrastructure. The systematic campaign targets energy, finance, and government networks worldwide, prompting joint warnings from NSA, CISA, and 11 allied nations.